Odoo

First CVE: Apr 9, 2019Active for: 7 years
34
CVEs Published
More CVEs Published than 50% of tracked CNAs
8.5
Avg CVEs / Year
More Avg CVEs / Year than 49% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Odoo as a CNA, 100.0% affect products that Odoo develops as a vendor.

100.0%
Self-reported: 34Third-party: 0

Of all the CVEs published that affect products developed by Odoo, 63.0% are self-published by Odoo as a CNA.

63.0%
37.0%
Self-published: 34Published by other CNAs: 20

Trends Over Time

The number and severity of CVEs published by Odoo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2019
7 years ago
Most Recent CVE
Feb 25, 2025
514 days ago

Top CVEs

All CVEs published by Odoo as a CNA, regardless of affected vendor or product.

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a vi
Apr 25, 20236.133NOYES
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request.
Apr 9, 20198.831NONO
A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation.
Apr 25, 20239.128NONO
A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute ar
Dec 22, 20208.828NONO
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenan
Apr 25, 20238.727NONO
A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server.
Apr 25, 20238.727NONO
Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty databas
Dec 22, 20209.127NONO
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, inc
Apr 25, 20238.126NONO
Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their
Dec 22, 20208.826NONO
Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that be
Apr 25, 20237.525NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA34 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network34 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None23 (67.6%)
Unknown0 (0.0%)
Required11 (32.4%)
Privileges Required
Low18 (52.9%)
High4 (11.8%)
None12 (35.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (34 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.9% of CVEs· 89th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Odoo as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Odoo as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs